Mosquitto
What it is: An open-source MQTT broker from the Eclipse Foundation. It implements MQTT 5.0, 3.1.1 and 3.1, is lightweight and runs on everything from single-board computers to servers. The project also provides a client library and the mosquitto_pub and mosquitto_sub tools.1 In smart homes it's the typical broker for Zigbee2MQTT, Home Assistant and Node-RED. HA recommends it as your own broker.2
Overview
| Project | Eclipse Mosquitto, Eclipse Foundation1 |
| License | EPL / EDL1 |
| Protocols | MQTT 5.0, 3.1.1, 3.11 |
| Current version | 2.1.2 (2026-02-09), 2.1 series since 2026-01-293 |
| Docker image | eclipse-mosquitto (Umbrel: 2.1.2-alpine)1 |
| WebSockets | built in since 2.1, no libwebsockets3 |
| Authentication | username and password (file or plugin), Dynamic Security, ACL, TLS4 |
Version 2.1: what to watch out for
According to the3:
password_fileandacl_fileare deprecated in favour of the password-file and acl-file plugins and will be removed in 3.0. Invalid content in these files now makes the broker quit on reload.max_packet_sizenow defaults to 2 MB instead of 256 MB. If you send large messages, raise it.- Client-side TLS 1.1 and OpenSSL older than 3.0 are no longer supported.
- New:
accept_protocol_versions(limit MQTT versions per listener),--test-config(validate config before starting), persist-sqlite plugin, PROXY protocol v1/v2. - 2.1.1 and 2.1.2 are bugfix releases. The broker refuses to start with
persistence trueand a persistence plugin enabled at the same time.
Mosquitto on Umbrel
The official Umbrel App Store has a Mosquitto 2.1.2 app (automation category).1
| Containers | broker (eclipse-mosquitto 2.1.2-alpine, runs as user 1000:1000) and web (nginx with instructions) |
| Ports | 1883 MQTT to the LAN, 9021 web app and MQTT over WebSockets (nginx โ internal listener 9001) |
| Configuration | ~/umbrel/app-data/mosquitto/data/config/mosquitto.conf, data and logs next to it in data/ |
| Editing | Settings โ Advanced settings โ Terminal โ umbrelOS, sudo nano on the config |
| Dependencies | the Zigbee2MQTT app requires Mosquitto and connects to mqtt://mosquitto_broker_1:1883 |
| Client | MQTTX Web from the Umbrel App Store (port 9021) or MQTT Explorer (port 1883) |
Umbrel allows anonymous clients
The app's defaultmosquitto.confhasallow_anonymous true, with no password or ACL set.1 Mosquitto 2.x itself rejects anonymous clients by default.4 So anyone on the network can publish to the broker on port 1883. The app itself recommends setting up authentication if the broker is to be reachable from the internet.
Synthesis: Home Assistant on Umbrel is a container install without apps (formerly add-ons)5, so the HA OS "Mosquitto app" isn't available. The broker is the separate Mosquitto app, and HA connects to it in the MQTT integration via the Umbrel address and port 1883. Procedure incl. passwords and Zigbee2MQTT: Mosquitto on Umbrel step by step.
Security
- Without TLS, passwords travel over the network in clear text; ACLs restrict topic read and write per user.4
- Synthesis: password-protect the broker even on a home network and only let in devices that need MQTT. Smart-home devices belong in their own VLAN, see VLAN. Don't expose the broker to the internet; use a VPN for remote access.
- After enabling passwords on Umbrel, clients need updating too. The Zigbee2MQTT app only sets the server address.1
Integrations
- Home Assistant: MQTT integration, discovery with the
homeassistantprefix, birth and LWT messages.2 - Zigbee2MQTT: publishes Zigbee device state to MQTT and receives commands.
- Node-RED and SMLIGHT SLZB-OS also speak MQTT, see MQTT.
Related
- Mosquitto on Umbrel step by step, MQTT, Zigbee2MQTT, Home Assistant, Node-RED, Umbrel Home, Docker, VLAN
Sources
- Umbrel App Store: the Mosquitto app โ โ the Mosquitto app in the Umbrel App Store (manifest, compose, default config).
- Home Assistant documentation (installation, concepts, backups, MQTT, ZHA, SMLIGHT, UniFi) โ โ the MQTT integration in HA, recommended broker.
- Mosquitto blog: release notes 2.0.19โ2.1.2 โ โ Mosquitto blog, changes from 2.0.19 to 2.1.2.
- Mosquitto: mqtt(7) and mosquitto.conf(5) โ โ mqtt(7) and mosquitto.conf(5), default behaviour and security.
- umbrelOS / Umbrel Home (README, app store, product page) โ โ HA on Umbrel as a container install.
Intellihome